Skip to main content

folkfox

Skip to main content
Skip to content
CYBERSECURITY COMPLIANCE

Twenty five days until the cyber resilience act starts counting hours

On 11 September 2026 a reporting duty stops being a roadmap item and becomes a stopwatch. For anyone selling security to European manufacturers, that is not a fear pitch, it is a diary entry with 25 days of runway on it.

Quick answerFrom 11 September 2026 the cyber resilience act requires an early warning within 24 hours of becoming aware of an actively exploited vulnerability, a full notification within 72 hours, and a final report within 14 days of a fix.
Section 01

What the cyber resilience act asks for on 11 September#

A fox does not argue with the weather. It reads a ridge, watches which way the wind walks, and shifts its route while the ground is still soft. The cyber resilience act offers security marketers exactly that courtesy: a date, published in advance, that nobody can honestly claim crept up on them in the dark.

From 11 September 2026, manufacturers are required to report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements, according to the European Commission's reporting obligations page, last updated on 31 July 2026. The duty covers products already sitting in the market. Not the firmware that ships next quarter, the firmware that shipped four quarters ago and is still humming away in somebody's plant room.

The shape of the duty is a countdown in three parts. An early warning within 24 hours of becoming aware. A full notification within 72 hours. Then a final report, due no later than 14 days after a corrective measure is available for an actively exploited vulnerability, and within a month for a severe incident. Those are the Commission's stated windows, and they are the spine of every sensible campaign between now and the autumn.

Twenty five days separate this piece from that date. The deadline does not negotiate with readiness and it does not wait for the quarter to close. It arrives on the eleventh whether the runbook is written, whether the asset register was refreshed this year, whether the one engineer who knows where the firmware for the 2019 gateway lives is on annual leave in Andalusia. That asymmetry, a fixed date set against uneven preparation, is precisely why the cyber resilience act is a marketing moment rather than a scare story.

cyber resilience act deadline: a painted fox holds a nearly empty hourglass beside a still-sealed postbox
Twenty five days of sand, and a channel that opens on the day the clock stops.

Most vendor content will spend three weeks shouting the date. The better trade is quieter: explain what the cyber resilience act does to a working week, then show which part of it a buyer can survive without buying anything at all. Trust earned in August gets a call returned in October.

Who the cyber resilience act actually binds#

The duty sits with manufacturers of products with digital elements, the category set out in Regulation (EU) 2024/2847 itself. In practice that phrase pulls in many more firms than the word manufacturer suggests: anyone shipping connected hardware, anyone shipping the software that runs on it, and a long tail of companies who have never once thought of themselves as regulated entities.

For a security vendor, that long tail is the list. Every name on it now holds a diarised question it mostly cannot answer, and the cyber resilience act put the date on that question rather than your marketing team. Squandering that on a countdown widget would waste a good winter.

0 hours

from becoming aware to the early warning, for an actively exploited vulnerability in a product already on the market

European Commission

Section 02

The 24, 72 and 336 hour clock, drawn to scale#

Numbers inside a regulation read as prose. Drawn on a single axis they read as pressure. So here is the cyber resilience act clock in hours, converted from the deadlines the European Commission states, because hours are the unit an on-call engineer actually feels and the gap between the first window and the last is the whole story.

Three windows, one scale
Dumbbell chart plotting three cyber resilience act reporting windows on one scale in hours: early warning at 24 hours, full notification at 72 hours, final report at 336 hours.AwarenessDeadlineEarly warning: 0 to 24Early warning24Full notification: 0 to 72Full notification72Final report: 0 to 336Final report336
The gap widens fast: 24 hours to the early warning, 72 to the full notification, 336 to the fourteen day final report, converted to hours from the European Commission's stated deadlines. The fourteen days run from the moment a corrective measure is available, not from awareness.

The first hop is brutal and the last is generous, and almost all readiness work goes into the wrong one. Twenty four hours is not a process, it is a reflex, and a reflex must be rehearsed rather than documented. The 336 hour tail is the part teams plan for happily, because it looks like work they recognise: write-ups, reviews, sign-off, a slide.

The same clock, reconciled
The same clock, reconciledWaterfall chart reconciling the cyber resilience act reporting clock from zero at awareness through 24, 48 and 264 additional hours to a total of 336 hours.Awareness: 0Awareness0Early warning: 24Early warnin24Full notification: 48Full notific48Final report: 264Final report264336 hours: 336336 hours336
Twenty four hours, then 48 more, then 264 more: the fourteen day final report closes a clock that opened at zero, arithmetic taken from the European Commission's stated deadlines.

Read that waterfall the way a fox reads a hedgerow, from the gap at the near end rather than the length of the whole run. The first 24 hours decide whether anything afterwards happens on time. Miss that window and every later stage of cyber resilience act reporting gets written in retrospect, by people already apologising.

The three windows are not three documents#

One correction worth making early, because it changes the product story. Anyone writing about cra compliance tends to describe three reports. There is one disclosure, told in three stages, each building on the last. A tool that drafts stage one automatically has already made stages two and three cheaper and calmer, which is a far stronger claim than a countdown clock parked on a landing page.

It also reframes the buying question. The manufacturer is not shopping for a filing form. They are shopping for the ability to know, quickly and defensibly, what happened and to what. Everything else in the cyber resilience act follows from that single capability, and every honest vendor page should say so before it mentions a feature.

Section 03

Why vulnerability reporting breaks on the inventory, not the form#

The sharpest sentence written about this landed on X at 11:30 this morning, under eight hours before this piece went out. SBOMFlow posted a countdown to 11 September and closed with six words that belong above every product roadmap in Europe.

You cannot report what you cannot inventory.
SBOMFlow on X, 17 August 2026

A reply in the same thread, from boardyai, supplied the timing: that last line is the one teams will discover too late. Both posts are practitioner commentary rather than guidance, and they are best read as a mood reading of the market rather than a legal position on anything.

Here is the mechanical version of the same point. The 24 hour clock starts at awareness, and awareness means somebody somewhere has connected an exploited weakness to a product you shipped. To do that you must know which components sit inside which products, which versions are live in which fields, and who owns the answer when the usual owner is unreachable. Vulnerability reporting under the cyber resilience act is only the visible half of the duty. The invisible half is a component inventory most manufacturers have never been obliged to hold.

ENISA is building the channel that receives it. Its Single Reporting Platform page describes the platform as the technical tool for reporting actively exploited vulnerabilities and incidents affecting products with digital elements in the EU Digital Single Market, and says that from 11 September 2026 onwards it will be used by CSIRTs and manufacturers for mandatory reporting, and could be used by any natural or legal person for voluntary reporting. The agency also notes that throughout 2025 and 2026 it has been taking the necessary steps to support the platform's implementation.

Note the tense, then resist the temptation to make a scandal of it. ENISA does not say the platform is late, and no vendor blog should say it either. The honest framing is narrower and far more useful: the obligation carries a fixed date, and the tooling around it is described in the future tense on the agency's own page. Readers draw their own quiet conclusion, and they remember the brand that let them draw it.

What the incidents actually look like#

The industry's favourite illustration for all of this is a compromised turbine, sparks optional. The quarter's data does not support the picture. Dragos counted 1,140 ransomware incidents affecting industrial organisations worldwide in Q2 2026, a 12% increase over the 1,020 incidents recorded in Q1, with manufacturing carrying 747 incidents, 65% across all subsectors. North America took 514 of them. And in that whole quarter, Dragos observed no case in which a ransomware operator reached Stage 2 of the ICS Cyber Kill Chain or directly manipulated a control system.

Help Net Security, reporting the same analysis, breaks the quarter down further: construction 176, equipment manufacturing 114, organisations supporting ICS environments 117, transportation and logistics 95, food and beverage 70. By region, Europe took 316 incidents while the United States alone took 431, 38% of the worldwide total, with Asia on 172 and South America on 64. Qilin led the groups with 140 claims, down from 198 in Q1, ahead of Akira on 129 and The Gentlemen on 125.

Dragos frames the risk as being shaped less by novel malware written for control systems and more by adversaries' deepening focus on the enterprise IT systems that support operational technology environments. Fernando Cassina made the same point far more bluntly on X this afternoon, writing in Spanish; the translation here is folkfox's own. Industrial ransomware, he says, does not come in through the PLC. It comes in through the VPN without multi-factor authentication. His post is a single line and it does more work than most webinars.

That is the connective tissue between a threat report and a reporting deadline. The incidents that trigger a cyber resilience act notification will rarely look cinematic. They will look like a credential, a stale service account and a flat network, which is exactly what practitioners keep describing when nobody is selling anything.

A thread posted to r/cybersecurity at 09:00 UTC today is a good example, and it deserves a clear label: it is an anonymous practitioner account, not a verified incident report. The poster describes an artificial intelligence ticket-triage agent opening the internal wiki, following a link dropped in a page, and pulling down a config file with a live API key in it, while running as a service account that somebody who had already left the company had set up for a nightly export. The line that lands hardest is the one about identity: the login rules we are so proud of do not even touch it.

Section 04

Turning the cyber resilience act timeline into a content calendar#

Every marketer says they want a hook with a hard date on it. Here is one, printed by a regulator, with 25 days of runway and no ambiguity about when it expires. The cyber resilience act timeline is that rare campaign brief which writes its own urgency without needing a single adjective borrowed from a horror film.

The temptation is a countdown banner and a gated white paper. Resist both. A deadline campaign that trades on dread ages badly, because on 12 September the dread expires and the content dies quietly with it. Build instead for the question the buyer genuinely carries, which is not what the law says but whether anyone in the building could answer it on a wet Tuesday in November.

The 25 day sequence, in order
Publish the clock

One plain explainer of the cyber resilience act windows, 24 hours, 72 hours and 14 days, sourced to the European Commission, with the date in the heading. No gate, no form, no chatbot. This is the page you want quoted when somebody searches the deadline at midnight.

Answer the inventory question

Follow it with the harder piece: how a manufacturer works out which components sit inside which shipped products. This is where the buyer's real anxiety lives, and where most vendor content politely stops.

Show the reflex, not the report

Publish a one page runbook for the first 24 hours. Who declares awareness, who drafts, who signs, who sends, and what happens when that person is away. A rehearsal beats a roadmap every time.

Name the gap you do not fill

Say plainly which part of the duty your product does not touch. Candour on the boundary is what buys belief in the middle, and procurement will find the boundary anyway.

Book the October follow-up now

Plan the post-deadline piece before the deadline arrives: what the first fortnight of live reporting actually looked like. Nobody else will have that asset, because everyone else is still writing the countdown.

Sequence matters more than volume here. Publish the explainer before the tool, the tool before the case study, and the case study before the pitch, because buyer confidence climbs in that order or it does not climb at all. A campaign that opens with the pitch is a fox breaking cover in daylight.

Five cyber resilience act assets, five questions, and the evidence that each one actually landed rather than merely shipped.
WindowAssetQuestion it answersProof it landed
18 to 24 AugustThe clock explainerWhen does the duty start, and what is due when?Quoted rather than paraphrased in someone else's summary
25 to 31 AugustThe inventory pieceHow do we know what is inside what we shipped?Sales send it unprompted, without being asked to
1 to 7 SeptemberThe first 24 hours runbookWho does what on the day it actually happens?A prospect asks for a version with their own names in it
8 to 11 SeptemberThe boundary noteWhat does this product deliberately not do?Procurement stop asking the question on the call
Mid OctoberThe first fortnight reviewWhat did live reporting really look like?Cited by somebody who is not yet a customer

Regulators read commercial plans, and write down what they think#

This is not speculation. In August 2026 the Office of the Comptroller of the Currency refused bunq's application for a United States national bank charter, and Banking Dive, quoting the decision letter, reported that the applicant had failed to consider and plan for expenses that would likely be necessary to compete effectively in the market given its lack of name recognition. The Paypers dates the letter to 4 August 2026, and the decision itself is published as Corporate Decision #1384.

That is a banking story rather than a cyber resilience act story, and the parallel is deliberately narrow. Brand recognition stopped being a soft metric the moment a supervisor priced it as a cost of entry, in writing, in a refusal. Run the logic in reverse for a manufacturer facing a dated duty and it holds: the ability to demonstrate readiness is part of the commercial case now, not a document filed politely afterwards.

The wider calendar reinforces it. Europe has stacked its dated duties tightly together. The AI Act implementation timeline records that on 2 August 2026 the remainder of the AI Act started to apply, except Article 6(1), that Member States had to ensure their competent authorities had established at least one national regulatory sandbox by that date, and that Article 6(1) and its corresponding obligations start to apply on 2 August 2027. Systems inside the large-scale IT systems listed in Annex X have until 31 December 2030 to be brought into compliance.

Read that beside the cyber resilience act and a pattern surfaces plainly. Buyers are not facing one deadline, they are facing a queue of them, arriving in a fixed order at a fixed pace. The vendor who maps the queue calmly is worth more than the vendor who shouts about one entry in it, and the map is cheaper to make than the shouting is to run.

Section 05

What to publish before the eleventh, and what to prove after#

Cyber resilience act compliance is not a thing a manufacturer buys in August and finishes in September. It is a standing capability with a rota attached, and content that treats it as a one-off purchase will be quietly ignored by the person who has to run it every quarter for the next decade.

So the writing job is narrower than it looks. Say what is true, say when it falls due, say what your product does and does not do about it, and put a name on the page. The market is drowning in generated summaries of the cyber resilience act; a specific, dated, checkable sentence is the scarce commodity, and scarcity is what gets cited.

Unquotable, undatable

Our platform delivers comprehensive, end-to-end readiness for the EU's new cybersecurity regime, empowering manufacturers to stay ahead of compliance risk across their entire product portfolio.

Specific, dated, checkable

From 11 September 2026 the cyber resilience act gives you 24 hours to send an early warning about an actively exploited vulnerability. This tool drafts that early warning from your component inventory in under an hour. It does not file it for you, and it does not cover severe incidents in your hosted services.

The second version survives a procurement review. The first survives roughly four seconds, and only because the reader was distracted. Notice that the honest version is also the one an answer engine can safely repeat, a happy accident of writing for humans who are about to be audited.

Own the proof, because the plumbing is contested#

There is a measurement warning folded into this month's news too. The evidence layer beneath marketing is itself being argued over in court. MediaPost reported that Google filed an amended complaint against SerpApi alleging it bypassed technological safeguards, three weeks after a district judge dismissed the original complaint and left Google able to proceed only on claims about content it licensed from third parties.

The practical lesson for a security brand is small and sturdy: build proof you own, on pages you control, rather than proof that depends on somebody else's access to somebody else's index. A published runbook, a dated explainer and a named author are assets no ruling revokes. A dashboard screenshot is a tenancy.

Two folkfox pieces cover this same terrain from neighbouring verticals, and both are worth a skim before briefing anything: the one on sports betting advertising meeting its compliance moment, and the one on buy now pay later becoming credit in July. Different sectors, identical shape: a dated rule, a scramble, and one brand that had already published the plain explanation.

If the work is the programme rather than the pitch, that is what folkfox content marketing builds, with SEO and GEO services making the pages quotable and brand strategy deciding what the company sounds like while the clock is running. The same discipline runs through FinTech marketing, where dated regulation is simply the weather, and through paid search when the launch window is short and the query volume is spiky.

The fox on the ridge does not sprint at the first sound in the undergrowth. It waits, works out which way the trail runs, and moves once, cleanly, while everything else is still crashing about. Twenty five days is plenty of time to publish something true about the cyber resilience act. It is nowhere near enough to build a reputation from scratch on 12 September, which is precisely why the sensible teams start tonight.

Questions

Frequently asked questions#

What is the cyber resilience act timeline for reporting an exploited vulnerability?

The European Commission sets three windows. An early warning within 24 hours of becoming aware, a full notification within 72 hours, and a final report no later than 14 days after a corrective measure is available for an actively exploited vulnerability. Severe incidents get a month for the final report. The duty starts on 11 September 2026.

Does cra compliance apply to products that are already on sale?

Yes. The European Commission states that from 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements. The cyber resilience act reaches products already placed on the market, so it is not limited to whatever ships after the date.

Who is responsible for cyber resilience act compliance inside a manufacturer?

The duty sits with the manufacturer of the product with digital elements, as defined in Regulation (EU) 2024/2847. In practice that means a named owner who can declare awareness, a drafter, a signer and a sender, with cover for holidays. If nobody can name those four people, the 24 hour window is theoretical.

Where does vulnerability reporting under the act actually go?

ENISA describes its Single Reporting Platform as the technical tool for reporting actively exploited vulnerabilities and incidents affecting products with digital elements in the EU Digital Single Market, used by CSIRTs and manufacturers for mandatory reporting from 11 September 2026 onwards, and available for voluntary reporting by others.

Three weeks before the 11 September deadline, a compliance consultancy's readiness assessment finds a patchwork rather than a plan.

Is this the only European deadline landing on the calendar this year?

No. The AI Act implementation timeline records that the remainder of the AI Act started to apply on 2 August 2026, except Article 6(1), which follows on 2 August 2027. Systems inside the large-scale IT systems listed in Annex X have until 31 December 2030. Buyers are facing a queue of dated duties.

Should a security brand run a countdown campaign to 11 September?

Only if the countdown carries something useful. A banner of falling numbers expires the moment the date passes. An explainer, a first 24 hours runbook and an honest note about what your product does not cover keep earning attention in October, when the first real reports are being filed and everyone is comparing notes.

Keep reading

Read more on this topic#

Twenty five days is enough to publish something true

Dated, sourced, quotable content for security brands selling into regulated markets is what folkfox builds: explainers that get cited, runbooks that get shared, and proof you own on pages you control.